> For the complete documentation index, see [llms.txt](https://docs.expel.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.expel.io/connect-your-technology/about-integrations/about-siem-integrations-and-connections.md).

# About SIEM Integrations and Connections

There are security devices with **SIEM-based technology** (like Splunk) that you may integrate via a direct API connection, and there are **via SIEM connections** that can be leveraged for supported vendor technology. A via SIEM connection can be set up in lieu of a direct API connection, or it can be used to onboard vendor technology that we currently only support by connecting via a SIEM.

## About SIEM Integrations <a href="#h_01k1eeqqca46spd009rqtk9rhr" id="h_01k1eeqqca46spd009rqtk9rhr"></a>

### Ingestion and Triage Process <a href="#h_01k1eeqqcb8j96bp5rpqxvjg0x" id="h_01k1eeqqcb8j96bp5rpqxvjg0x"></a>

For SIEM-based technology that is set up in Workbench as a direct API connection, we leverage your SIEM's out-of-the-box detection rules and/or your custom detection rules to map the SIEM alerts to our own ingestion criteria. This enables our [Josie bot](/workbench-reference/expel-terminology.md#josie) to follow the normal [event triage process](/workbench-reference/alerts/how-expel-alerts-work.md#event-triage-process), and to create an [Expel Alert](/workbench-reference/alerts/how-expel-alerts-work.md) that is sent to our SOC analysts for analysis. We also run queries against your SIEM logs to search for additional types of data, which may result in the creation of an Expel Alert.

### Console Access <a href="#h_01k1eeqqcc7xp79c12nztpw5rp" id="h_01k1eeqqcc7xp79c12nztpw5rp"></a>

A SIEM alert does not typically include all of the contextual timeline activity surrounding an event of interest, and sometimes we cannot get all necessary data via API. In those cases, we will ask you for a certain level of console access during onboarding. Granting it is optional, but we strongly recommend you provide it.

The level of access that we require is meant to support essential triage and research activities, and to help us determine the vector and extent of attacker activity for an identified threat. At minimum, we will ask for visibility into alert data, timeline events recorded, and live response/real time response shell (if applicable).

For more information about console access, see [Why Expel Asks for Console Access](/connect-your-technology/about-integrations/why-expel-asks-for-console-access.md).

### Setup Process <a href="#h_01k1eeqqcd7tvj8kp2et3g21yc" id="h_01k1eeqqcd7tvj8kp2et3g21yc"></a>

Setting up a SIEM device follows the same general process as setting up any direct integration in Workbench. You may, however, have a second step if you wish to use custom detection rules:

1. Set up the **SIEM device** in Workbench by locating its setup guide. <button type="button" class="button primary" data-action="search" data-icon="magnifying-glass">Find your setup guide…</button>
2. If you have **custom detection rules** enabled or if you wish to add some, [follow the detection rule submission process](/connect-your-technology/about-integrations/about-siem-integrations-and-connections.md#h_01k1eeqqcj8yhaynheewq6vvwd).

* Your device will show as "Healthy" in Workbench, but Expel Alerts will not appear until the rule review process is complete.

{% hint style="info" %}
Setting up your device as a first step (including granting all [necessary console access](#h_01k1eeqqcc7xp79c12nztpw5rp)) greatly facilitates the evaluation and approval process for your custom detection rules.
{% endhint %}

### Criteria for Detection Rule Acceptance <a href="#h_01k1eeqqcga7gqdry9bpv6m23h" id="h_01k1eeqqcga7gqdry9bpv6m23h"></a>

Our SIEM-based technology integrations do not necessarily support all of your custom detection rules. We will partner with you to evaluate all detection rules and inform you on how much we can support them based on the following criteria:

* **Fidelity** - the detection rule should have an alert volume that suggests high fidelity (for example, an average weekly alert volume less than 10 suggests the rule has high fidelity)
* **Redundancy** - the detection rule name, description, and query should not duplicate (or suggest a duplication of) alerts that would surface through a direct API integration with a non-SIEM technology
* **Evidence** - the detection rule must provide us with an adequate number of artifacts to action upon (two or fewer artifacts suggests insufficient information for our SOC analysts)
* **Scope** - the detection rule name, description, and query must align with your service and should not be written for a different category of service

If we are unable to support your custom detection rule because it does not meet the criteria above, we will let you know so that you can make modifications and resubmit it to us.

### How to Submit Your Custom Detection Rule(s) <a href="#h_01k1eeqqcj8yhaynheewq6vvwd" id="h_01k1eeqqcj8yhaynheewq6vvwd"></a>

To submit your new custom detection rule(s), [contact Support](/support/how-to-reach-us.md) and **be sure to include all details (rule name, description, query) in your request**. You may submit multiple custom detection rules in a single support request.

We will then review the submission and create our own custom mapping to determine how each rule should be handled. Please allow 10 to 20 business days for us to complete this process and notify you of a decision. If your custom detection rule did not meet our [criteria for acceptance](#h_01k1eeqqcga7gqdry9bpv6m23h), you may make changes and re-submit it to us through the same process.

{% hint style="info" %}
If you need expedited processing for a small amount of urgently needed custom detection rules, let us know in your initial request and we will do our best to meet your timelines.
{% endhint %}

## About via SIEM Connections <a href="#h_01k1eeqqcmef9jbdzkgcnaq7vx" id="h_01k1eeqqcmef9jbdzkgcnaq7vx"></a>

A direct API connection is the conventional (and more robust) way to set up your integration if it is available. But in cases where we do not yet support an API connection for the technology, or where you already have some internal SOC tuning in place for your vendor alerts, you can set up a connection via a SIEM instead. **You must use a supported SIEM to set up this type of connection, and you must also connect to a supported vendor technology.**

Visit the [Expel Integrations page](/connect-your-technology/about-integrations/expel-integrations.md) to see which integrations allow you to connect via a SIEM, and which SIEMs are supported.

### Considerations and Limitations <a href="#h_01k1eeqqcmrf23k78ed40p0rvd" id="h_01k1eeqqcmrf23k78ed40p0rvd"></a>

Our ability to perform follow-up or triage for your data is limited in this type of connection, as we do not have access to the full security data for the source nor do we have access to the console. This is why a direct API connection is the preferred method of integration when available—especially in cases where a vendor alert from a [supported (direct API) integration](/connect-your-technology/about-integrations/expel-integrations.md) is only passing through a SIEM because of a custom detection rule.

However, if the vendor alert coming into your SIEM has already been tuned by your own SOC, the SIEM alert is likely stronger than the original vendor alert. In these instances, a via SIEM connection may be preferable to a direct API connection. **But you must choose one or the other.** If you have already set up your integration as a direct API connection, you should not also create a via SIEM connection due to duplication issues.

### Ingestion and Triage Process <a href="#h_01k1eeqqcncfwmxyytjjjgajz5" id="h_01k1eeqqcncfwmxyytjjjgajz5"></a>

[Expel Alerts](/workbench-reference/alerts/how-expel-alerts-work.md) are created by ingesting your SIEM alerts and also by looking at its log data. This will result in any of the following triage actions:

* Our SOC analysts creating an [Investigation](/workbench-reference/investigations-and-incidents/understanding-investigations.md)
* Our SOC analysts storing evidence from the SIEM logs that we can use to inform future Investigations
* Our SOC analysts sending a question directly to you about an event's authorization (or lack of authorization) that is referenced in the Expel Alert

{% hint style="warning" %}
We can only ingest SIEM alerts for connected vendor technology that we [already support via a direct integration](/connect-your-technology/about-integrations/expel-integrations.md).
{% endhint %}

### Setup Process <a href="#h_01k1eeqqcqwebqscecnhc0f3c6" id="h_01k1eeqqcqwebqscecnhc0f3c6"></a>

Setting up a via SIEM connection requires three steps:

1. Make sure your **SIEM's data sources** are logging properly.
   * You will need to specify which logs the SIEM should ingest, where they should be stored, and any other data quality information that should be included.
   * If you need help with this step, follow your SIEM's documentation or work with your SIEM's representative.
2. Set up the **SIEM as a security device** in Workbench by locating its setup guide. <button type="button" class="button primary" data-action="search" data-icon="magnifying-glass">Find your setup guide…</button>
3. Set up a **via SIEM connection as a separate security device** in Workbench (you will find these instructions in your setup guide).

{% hint style="warning" %}
Custom detection rules cannot be used for a via SIEM connection.
{% endhint %}

## FAQs <a href="#h_01k1eeqqcsf6dragb6jjzkv3rw" id="h_01k1eeqqcsf6dragb6jjzkv3rw"></a>

**Do all SIEM integrations receive the same level of support?**

Our SIEM integrations are broken into tiers. See [MDR SIEM Tiers](/connect-your-technology/about-integrations/tiers-and-support.md) for more information.

**Is there a security device tuning period after setup?**

Yes, for about 48 hours. Sometimes we are not able to apply the proper tuning on our end, so we may reach out with tuning suggestions for you to apply within your SIEM. [Learn more about device tuning](/workbench-reference/alerts/how-expel-alerts-work.md#device-tuning).

**Who maintains a custom detection rule after it is implemented?**

Our SOC analysts may apply minor suppressions to maintain fidelity but, ultimately, you are responsible for the performance of the rule and its adherence to our criteria.

**Why might you adjust the severity of a custom detection rule?**

We make decisions about how to surface your custom detection rules according to their projected fidelity and impact. If the alert volume begins suggesting a different level of fidelity that does not align with the currently assigned severity, we will adjust it.

**Do you support Windows event logs?**

No, we no longer support this type of SIEM log.

## Find Your Setup Guide(s) <a href="#h_01k1eeqqcv1axvezh31vcnq1wj" id="h_01k1eeqqcv1axvezh31vcnq1wj"></a>

If you are ready to get started, use search for your technology's setup guide.

<button type="button" class="button primary" data-action="search" data-icon="magnifying-glass">Find your setup guide…</button>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.expel.io/connect-your-technology/about-integrations/about-siem-integrations-and-connections.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
